GROUP-IB researchers have identified Vwork, a malicious Android utility used alongside the Gigabud banking trojan by the GoldFactory cybercrime group. The campaign targets mobile banking users in 11 countries: Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye and a GCC member state. Attackers distribute the malware through phishing websites, messaging services and social-media promotions posing as airlines, tax authorities and government portals.
In Indonesia, telemetry recorded 1,469 compromised devices and 1,281 stolen account credentials between February and July 2026, with estimated losses of about US$960,939.
After installation, Gigabud requests Accessibility access, overlay permissions and exemption from battery optimisation. Accessibility access gives operators functional control of the device, while overlays can capture banking credentials and the device’s screen-unlock code. Gigabud inventories installed applications, identifies banking apps and can display fraudulent login screens over genuine ones.
It then installs Vwork, a weaponised fork of the open-source Shelter application, to clone a banking app into an Android Work Profile. Running the clone in a separate profile is intended to evade security tools monitoring only the personal profile. Operators can then conduct transfers from the cloned app while a black screen hides the activity.
Vwork has no independent command-and-control capability; Gigabud provides communications and issues commands including `initVwa`, `cloneApp` and `uploadCloneApps`. Group-IB said newer Gigabud variants also support live remote desktop control and encrypted exfiltration of device and credential data. Defenders should monitor for unexpected work profiles, suspicious administrative or cloning applications, rapid app installations, overlay abuse and transactions from newly created profiles. Users should avoid unofficial downloads, scrutinise Accessibility requests and factory-reset devices if an unauthorised profile is found.